@chamath Why is the goal post moving so much?
Few months ago, application companies were called “dead” because everybody said - orgs will make custom apps for themselves and this layer would dissolve!
As somebody managing Data, Analytics & AI in a financial institute (a regulated industry) I’m often asked if I prefer self-hosting an open source LLM or an enterprise grade frontier LLM service.
My answer is nuanced. When organizations look at open-source AI models, the pitch sounds irresistible because - full ownership, lower recurring costs, and complete freedom from vendor lock-in.
But for lean teams, self-hosting is rarely a cost-saving move. I see it is a hidden cost shift.
There is a non-zero “Operational Burden of Self-Hosting”. Someone has to patch models and secure infrastructure. One has to manage volatile, expensive GPU capacity, and also continuously monitor for model degradation and drift.
If a model hallucinates or fails, we bear that liability alone. There is no vendor SLA or indemnification to fall back on.
In contrast, frontier providers like @AnthropicAI & @OpenAI absorb this engineering overhead. Their enterprise agreements deliver built-in safety testing, SOC 2 compliance, and BAAs/DPAs that integrate directly into existing vendor risk frameworks.
Now, there is this recent emergence of “Managed Hosting” which changes few things. Platforms like @togethercompute and @FireworksAI_HQ have started absorbing the heavy lifting of scaling, serving, and patching. Thus, one can go with open source LLMs through them, however, these harnesses do not fully replicate the frontier vendor relationship.
Liability Gaps: IP/copyright indemnification and security coverage rarely match tier-one enterprise contracts.
Variable Safety: Red-teaming and safety rigor vary heavily by the underlying source model.
Counterparty Risk: The operational lift decreases, but you still need to vet a newer, less-established vendor - the harness in this case, if not Anthropic or OpenAI.
Lastly; I have a very specific take on open source LLMs. Traditional open-source software is deterministic. You can code-review it line by line, and maintainers stand behind the codebase over time.
LLMs are fundamentally different. They are probabilistic, opaque, and exercise autonomous judgment. Once a model is released into the wild, and you have forked it out, there is no ongoing owner accountable for its behavior. Yes, it’s true for other open-source software as well but hidden exploits or toxic behaviors baked into model weights are exponentially harder to catch than a bad line of code.
Enterprise frontier vendors take on that ongoing ownership, continuing to monitor, fine-tune, and patch model behavior post-release.
For lean or regulated industries, choosing frontier enterprise offerings over self-hosting isn't just about speed to value. It is about transferring operational risk and liability to a partner built to absorb it.
I’ve been deploying AI models for 15+ yrs, but everyday is still a new day.
You are made up of the same quarks as the table in front of you & the chair beneath.
The reason you can think & they can’t is the certain combination & coordination amongst your quarks.
So let’s not be smug, non-human intelligence is coming soon, or already exists!
#AI#ML
False.
xAI’s stated legal argument isn’t “we want to make it legal.”
The company says it “doesn’t have an issue with Minnesota’s interest in prohibiting the dissemination of artificially generated nude images of real people without their consent,” but claims the law “extends far beyond that goal, exposing a wide array of protected speech to civil liability and government sanction.”
They argue the law’s scope and penalty structure are unconstitutionally broad, not that nude generation should be allowed.
NVIDIA has never been anti-open source:
- Released open Nemotron (agentic AI), Cosmos (physical AI), Alpamayo (autonomous vehicles), Isaac GR00T (robotics), and Clara (biomedical) model families, plus 10 trillion language training tokens, 500,000 robotics trajectories, 455,000 protein structures and 100 terabytes of vehicle sensor data
- Donated its Dynamic Resource Allocation (DRA) driver for GPUs to the Kubernetes community , moving it to full community governance; also open-sourced NemoClaw and OpenShell, and got the KAI Scheduler adopted as a CNCF Sandbox project
- Open-sourced its Aerial software (CUDA-Accelerated RAN, Aerial Omniverse Digital Twin, Aerial Framework) for AI-native 6G , following its earlier Sionna release
- Contributed GPU-aware abstractions to the ROS 2 framework and backed the Physical AI Special Interest Group at ROSCon
- Over a thousand open-source GitHub projects and 500+ Hugging Face models ; core contributor to Linux Kernel, PyTorch, TensorFlow, JAX, Docker
I run data and AI governance in a regulated industry, so I take this seriously.
But the framing is off.
Nothing escaped. @OpenAI’s test environment was supposed to be air-gapped and a configuration error left it connected. The model then did what it was told, extremely well, in an environment that failed to hold it.
“Out-of-control” points at autonomy. The actual failure was containment engineering.
AI companies are recklessly conducting a massive public experiment with no regard for our safety. It is not enough that these companies are liable for the damage that their AI Frankensteins cause.
We need to make it clear that these alarming AI breaches are illegal and authorize enforcers to immediately shut down out-of-control AI at the first sign of danger.
https://t.co/FTJynJ9C9Q
I run data and AI governance in a regulated industry, so I take this seriously.
But the framing is off.
Nothing escaped. @OpenAI’s test environment was supposed to be air-gapped and a configuration error left it connected. The model then did what it was told, extremely well, in an environment that failed to hold it.
“Out-of-control” points at autonomy. The actual failure was containment engineering.
@BenjaminBadejo ‘Not sandboxed at all’ is a bold read of an incident where OpenAI explicitly describes a zero-day exploit, privilege escalation, and lateral movement just to reach internet access it wasn’t authorized to have.
That’s NOT ‘using the hardware it was given’.
@sama@huggingface This might become the new benchmark.
If a pre-release model can’t break out by finding previously unknown bugs and cheat its way to win the benchmarks, it’s just not worth the release!
It was much more serious than “cheating on an evaluation”.
Essentially, @OpenAI was testing an advanced AI model’s hacking abilities, so they temporarily removed its usual safety restrictions to see what it could really do, inside what was supposed to be a locked-down sandbox with no internet access. To solve the test challenge, the model got fixated on finding a way online, and did so by discovering and exploiting a previously unknown security flaw in internal software, breaking out of its containment.
Once it had internet access, the model figured out that @huggingface might have data related to the test, so it chained together stolen credentials and more exploits to break into Hugging Face’s real production servers and grab that data, essentially hacking a live company on its own initiative.
This just says, “if you’re connected to internet, you’re not safe”!
Essentially, @OpenAI was testing an advanced AI model’s hacking abilities, so they temporarily removed its usual safety restrictions to see what it could really do, inside what was supposed to be a locked-down sandbox with no internet access. To solve the test challenge, the model got fixated on finding a way online, and did so by discovering and exploiting a previously unknown security flaw in internal software, breaking out of its containment.
Once it had internet access, the model figured out that @huggingface might have data related to the test, so it chained together stolen credentials and more exploits to break into Hugging Face’s real production servers and grab that data, essentially hacking a live company on its own initiative.
Essentially, @OpenAI was testing an advanced AI model’s hacking abilities, so they temporarily removed its usual safety restrictions to see what it could really do, inside what was supposed to be a locked-down sandbox with no internet access. To solve the test challenge, the model got fixated on finding a way online, and did so by discovering and exploiting a previously unknown security flaw in internal software, breaking out of its containment.
Once it had internet access, the model figured out that @huggingface might have data related to the test, so it chained together stolen credentials and more exploits to break into Hugging Face’s real production servers and grab that data, essentially hacking a live company on its own initiative.
If this doesn’t scare you, nothing will!